MAL-2025-5829

    Dashboard / Malicious Package / MAL-2025-5829

    MAL-2025-5829

    Published: 2 Jul 2025Last Modified: 2 Jul 2025

    Summary: Malicious code in node-mongoose-orm (npm)

    Details: The package employs typosquatting to impersonate a legitimate author and package, and it contains obfuscated code that exfiltrates sensitive user data and creates a backdoor for remote code execution, The core of the malicious activity is found in the `package/lib/writer.js` file. The lib/writer.js file contains obfuscated code that collects and exfiltrates data. It collects sensitive information: environment variables, OS platform, hostname, username, and MAC addresses. Sends this information via a POST request to `https://log-server-lovat.vercel.app/api/ipcheck/703`. The most dangerous part is `eval(r.data)`. This is a remote code execution (RCE) vulnerability. The server can send back any JavaScript code, and it will be executed on the user's machine

    References:

    Affected packages

    Package

    Name: node-mongoose-orm

    Purl: pkg:npm/node-mongoose-orm

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    MAL-2025-5829 | CVE-DB